Export limit exceeded: 404235 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (404235 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-107856 | 2026-10-09 | 4.5 Medium | ||
| CiviForm simplifies applications for government benefits programs by reusing applicant data across multiple benefit applications. Prior to 3.33.0, GET /admin/tiDash/editClientForm/:accountId verifies that the requester is a Trusted Intermediary but showEditClientForm performs a raw lookupAccount(accountId) without confirming that the citizen account belongs to the requester's trustedIntermediaryGroup. An authenticated Trusted Intermediary can enumerate accountId values and read the applicant display name, including the citizen's name and email address, for accounts outside the intermediary's group. This issue is fixed in version 3.33.0. | ||||
| CVE-2026-78835 | 2026-10-09 | N/A | ||
| Rocket Software Rocket Remote Desktop 18.0.8583.1 is vulnerable to Insufficiently Protected Credentials. | ||||
| CVE-2026-107843 | 1 Contao | 1 Contao | 2026-10-09 | 5.3 Medium |
| Contao is an Open Source CMS. From version 4.1.0 until 5.3.50 and 5.7.12, ModuleRegistration::compile() enters its follow-up registration branch on any POST to a page containing the registration module without verifying FORM_SUBMIT or the preceding captcha result. resendActivationMail() can then invoke OptInToken::send() without rate limiting, allowing an unauthenticated attacker to cause repeated activation emails to be sent to an address with a pending registration and to determine whether that pending registration exists. The branch is reachable only when reg_activate is enabled and the target has an unconfirmed registration and opt-in token. This issue is fixed in versions 5.3.50 and 5.7.12. | ||||
| CVE-2026-107844 | 1 Contao | 1 Contao | 2026-10-09 | 5.3 Medium |
| Contao is an Open Source CMS. From version 5.0.0 until 5.3.50 and 5.7.12, ImagesController joins the user-controlled {path} parameter to the configured image target directory with Path::join() but does not use Path::isBasePath() to verify that the canonical path remains inside that directory. An unauthenticated request containing encoded parent-directory segments can therefore return files under the project directory through BinaryFileResponse when their names use an extension allowed by contao.image.valid_extensions. The route can also reveal whether arbitrary paths exist, and debug responses can disclose absolute filesystem paths, but paths below the upload directory were not shown to be readable. This issue is fixed in versions 5.3.50 and 5.7.12. | ||||
| CVE-2026-107845 | 1 Contao | 1 Contao | 2026-10-09 | 9.3 Critical |
| Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, an unauthenticated visitor can submit a comment whose email or website metadata is rendered without sufficient attribute and URL encoding by listComments() in comments-bundle/contao/dca/tl_comments.php. When a backend user opens the Comments module, attacker-controlled script can execute in the Contao backend origin under that user's session. Unpublished comments remain visible to moderators, so moderation does not prevent exposure. This issue is fixed in versions 5.3.50 and 5.7.12. | ||||
| CVE-2026-107842 | 1 Contao | 1 Contao | 2026-10-09 | 5.3 Medium |
| Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, ModuleSearch can disclose protected page titles, URLs, and indexed context snippets to unauthenticated visitors when contao.search.index_protected is changed from enabled to disabled. Authorization metadata is stored per row in tl_search, but disabling the setting removes the protected-row filter without deleting rows indexed while protection was enabled. The protected pages continue to return an authorization response, so this issue exposes search metadata and indexed text rather than bypassing page access. This issue is fixed in versions 5.3.50 and 5.7.12. | ||||
| CVE-2026-93574 | 2 Io.netty, Redhat | 22 Netty-codec-http, Amq Broker, Amq Clients and 19 more | 2026-10-09 | 6.5 Medium |
| A flaw was found in Netty's `netty-codec-http` component. A remote attacker could exploit this vulnerability by sending a specially crafted HTTP/1.1 chunk-size token that includes post-digit whitespace. This incorrect parsing of the chunk size can lead to HTTP request smuggling. This allows an attacker to bypass security controls or access unauthorized resources in proxy/backend deployments. | ||||
| CVE-2026-93573 | 2 Io.netty, Redhat | 22 Netty-codec-http, Amq Broker, Amq Clients and 19 more | 2026-10-09 | 6.5 Medium |
| A flaw was found in Netty's HTTP/1.1 decoder. This vulnerability allows a remote attacker to bypass `Transfer-Encoding` header validation by splitting the `Transfer-Encoding` field across multiple headers, with the last field containing a non-final transfer coding like `gzip` or `deflate`. This bypass can lead to HTTP request smuggling, enabling attackers to bypass security controls, desynchronize request processing, or cause requests to be processed in an unintended context. | ||||
| CVE-2026-94067 | 2026-10-09 | 8.1 High | ||
| Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Fuelthemes The Voux thevoux-wp allows PHP Local File Inclusion.This issue affects The Voux: from n/a through 6.9.5. | ||||
| CVE-2026-94058 | 2026-10-09 | 7.1 High | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bracketweb Treck treck allows Reflected XSS.This issue affects Treck: from n/a through 1.0.0. | ||||
| CVE-2026-62042 | 2026-10-09 | 5.3 Medium | ||
| Missing Authorization vulnerability in unFocus Projects Scripts n Styles scripts-n-styles allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Scripts n Styles: from n/a through 3.5.8. | ||||
| CVE-2026-62026 | 2026-10-09 | 7.1 High | ||
| Cross-Site Request Forgery (CSRF) vulnerability in MIGHTYminnow Dashboard Notes dashboard-notes allows Cross Site Request Forgery.This issue affects Dashboard Notes: from n/a through 1.0.3. | ||||
| CVE-2026-108160 | 2026-10-09 | 7.5 High | ||
| AstronRPA through 1.1.6 contains a download of code without integrity check vulnerability that allows network attackers to deliver malicious updates by abusing the desktop client's auto-update mechanism. Attackers positioned between the client and server can serve a malicious update manifest and NSIS installer, which electron-updater installs without signature verification, executing code as the desktop user. | ||||
| CVE-2026-107935 | 1 Redhat | 8 Certifications, Edge Manager, Enterprise Linux and 5 more | 2026-10-09 | 9.3 Critical |
| A path traversal vulnerability was found in gvproxy, the network forwarder provided by the gvisor-tap-vsock package. The unauthenticated /services/forwarder/expose endpoint does not validate the caller-supplied socket path, allowing an attacker to delete arbitrary files on the host system. | ||||
| CVE-2026-107840 | 2026-10-09 | 7.5 High | ||
| yopass is a service for securely sharing secrets, passwords, and files. Prior to version 14.7.0, the Prometheus metrics middleware in pkg/server/server.go uses the attacker-controlled r.Method value directly as the method label for yopass_http_requests_total and yopass_http_request_duration_seconds. Because the catch-all route accepts arbitrary HTTP method tokens, an unauthenticated remote attacker can submit many unique methods and create metric series that the Prometheus registry never evicts. The resulting monotonic memory growth can OOM-kill the process, while the expanding registry also degrades /metrics scrape latency and can blind monitoring. This issue is fixed in version 14.7.0. | ||||
| CVE-2026-107812 | 1 0xjacky | 1 Nginx-ui | 2026-10-09 | 7.5 High |
| Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, the self-upgrade mechanism validates a downloaded binary only with a same-origin digest obtained from the same upgrade mirror. A compromised mirror or network attacker able to alter both responses can supply a malicious executable and matching digest. An operator-triggered upgrade is required, and the application installs and runs the attacker-controlled code in the Nginx UI process context on the next upgrade. This issue is fixed in version 2.5.0. | ||||
| CVE-2026-107802 | 1 Sumatrapdfreader | 1 Sumatrapdf | 2026-10-09 | N/A |
| SumatraPDF is a multi-format reader for Windows. In 3.6.1 and earlier, src/SelectionTranslate.cpp embeds selected or pasted translation text in quoted Windows command lines using incomplete quote-only escaping. The affected BuildGrokTranslateCmdLineTemp(), BuildClaudeTranslateCmdLineTemp(), and BuildCodexTranslateCmdLineTemp() functions can allow attacker-controlled text to inject model, working-directory, approval, or sandbox-bypass flags when the corresponding agentic CLI backend is installed and used. No broader impact is claimed beyond the advisory-supported conditions. No fixed version is available as of this review. | ||||
| CVE-2026-105883 | 2026-10-09 | 7.1 High | ||
| Missing Authorization vulnerability in ThemeHunk Th Shop Mania th-shop-mania allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Th Shop Mania: from n/a through 1.9.1. | ||||
| CVE-2026-104084 | 1 Smartertools | 1 Smartermail | 2026-10-09 | 8.8 High |
| SmarterMail before build 9777 contains a privilege escalation vulnerability where JWT access and refresh tokens embed a role claim at issuance that is not revalidated against the account's current role when redeemed through POST /api/v1/auth/refresh-token. Attackers who capture a refresh token issued before an administrator demotion, or a demoted user whose session was not actively polling at the time of demotion, can replay the stale token to obtain a new access token retaining the higher-privilege role (such as DomainAdmin or SysAdmin) until natural token expiry. | ||||
| CVE-2016-20098 | 2026-10-09 | 5.4 Medium | ||
| Moderator Toolbox (reddit-moderator-toolbox) before 4.0.14 contains a stored cross-site scripting vulnerability in the removalreasons module, which inserts subreddit toolbox wiki fields into popup HTML without encoding. Attackers who can edit the toolbox wiki page can plant JavaScript in fields like pmsubject, header, or reason titles to act with moderators' Reddit sessions. | ||||